Impact
A missing capability check inside the clear_all_log function in the Vchasno Kasa WordPress plugin allows an attacker to remove log entries without any authentication. This flaw does not provide code execution or direct access to sensitive data, but it removes the ability for site operators to audit activity or investigate incidents, effectively erasing forensic evidence. The weakness is identified as a missing privilege validation (CWE-862).
Affected Systems
The vulnerability affects all installations of the Vchasno Kasa plugin for WordPress via the MORKVA Vchasno Kasa Integration by bandido. Versions up to and including 1.0.3 are impacted; newer releases are presumed to have resolved the issue.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% shows that current exploitation probability is very low. The flaw is not listed in the CISA KEV catalog, suggesting no known public exploits. Attackers can trigger the clear_all_log operation remotely through the plugin’s exposed endpoint without authentication, making the exploitation path straightforward provided the plugin is active on the site.
OpenCVE Enrichment
EUVD